CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2017-2576

    Last Modified: 20 Apr 2025

    In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.

    Published: 20 Jan 2017
    6.1
    Medium

    CVE-2017-5542

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to inject arbitrary web script or HTML via the existing-folder parameter.

    Published: 20 Jan 2017
    9.8
    Critical

    CVE-2017-5543

    Last Modified: 20 Apr 2025

    includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request.

    Published: 20 Jan 2017
    5.3
    Medium

    CVE-2016-5012

    Last Modified: 20 Apr 2025

    In Moodle 3.x, glossary search displays entries without checking user permissions to view them.

    Published: 20 Jan 2017
    7.3
    High

    CVE-2016-7038

    Last Modified: 20 Apr 2025

    In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.

    Published: 20 Jan 2017
    5.3
    Medium

    CVE-2017-5541

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to rename arbitrary files via a .. (dot dot) in the existing-folder and new-folder parameters.

    Published: 20 Jan 2017
    5.5
    Medium

    CVE-2017-5844

    Last Modified: 17 Mar 2026

    The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted ASF file.

    Published: 20 Jan 2017
    7.8
    High

    CVE-2017-5669

    Last Modified: 20 Apr 2025

    The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not restrict the address calculated by a certain rounding operation, which allows local users to map page zero, and consequently bypass a protection mechanism that exists for the mmap system call, by making crafted shmget and shmat system calls in a privileged context.

    Published: 20 Jan 2017
    8.8
    High

    CVE-2017-5200

    Last Modified: 20 Apr 2025

    Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client.

    Published: 20 Jan 2017
    7.8
    High

    CVE-2017-5932

    Last Modified: 20 Apr 2025

    The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution metacharacter.

    Published: 20 Jan 2017
    5.5
    Medium

    CVE-2017-6498

    Last Modified: 20 Apr 2025

    An issue was discovered in ImageMagick 6.9.7. Incorrect TGA files could trigger assertion failures, thus leading to DoS.

    Published: 20 Jan 2017
    8.8
    High

    CVE-2017-5192

    Last Modified: 20 Apr 2025

    When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be bypassed.

    Published: 20 Jan 2017
    9.8
    Critical

    CVE-2015-8212

    Last Modified: 20 Apr 2025

    CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via crafted arguments, which are handled by a non-CGI aware program.

    Published: 19 Jan 2017
    7.8
    High

    CVE-2016-10075

    Last Modified: 20 Apr 2025

    The tqdm._version module in tqdm versions 4.4.1 and 4.10 allows local users to execute arbitrary code via a crafted repo with a malicious git log in the current working directory.

    Published: 19 Jan 2017
    8.8
    High

    CVE-2016-7793

    Last Modified: 20 Apr 2025

    sociomantic-tsunami git-hub before 0.10.3 allows remote attackers to execute arbitrary code via a crafted repository URL.

    Published: 19 Jan 2017
    9.8
    Critical

    CVE-2016-7794

    Last Modified: 20 Apr 2025

    sociomantic-tsunami git-hub before 0.10.3 allows remote attackers to execute arbitrary code via a crafted repository name.

    Published: 19 Jan 2017
    8.8
    High

    CVE-2016-9016

    Last Modified: 20 Apr 2025

    Firejail 0.9.38.4 allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.

    Published: 19 Jan 2017
    8.8
    High

    CVE-2016-5197

    Last Modified: 20 Apr 2025

    The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated intent URLs, which allowed a remote attacker who had compromised the renderer process to start arbitrary activity on the system via a crafted HTML page.

    Published: 19 Jan 2017
    8.8
    High

    CVE-2016-5196

    Last Modified: 20 Apr 2025

    The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin Policy amongst downloaded files, which allowed a remote attacker to access any downloaded file and interact with sites, including those the user was logged into, via a crafted HTML page.

    Published: 19 Jan 2017
    7.5
    High

    CVE-2017-5843

    Last Modified: 17 Mar 2026

    Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf.

    Published: 19 Jan 2017
    7.5
    High

    CVE-2017-5841

    Last Modified: 17 Mar 2026

    The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving ncdt tags.

    Published: 19 Jan 2017
    7.5
    High

    CVE-2016-10159

    Last Modified: 20 Apr 2025

    Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory consumption or application crash) via a truncated manifest entry in a PHAR archive.

    Published: 19 Jan 2017
    7.5
    High

    CVE-2016-10158

    Last Modified: 20 Apr 2025

    The exif_convert_any_to_int function in ext/exif/exif.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (application crash) via crafted EXIF data that triggers an attempt to divide the minimum representable negative integer by -1.

    Published: 19 Jan 2017
    9.8
    Critical

    CVE-2016-10160

    Last Modified: 20 Apr 2025

    Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PHAR archive with an alias mismatch.

    Published: 19 Jan 2017
    7.5
    High

    CVE-2016-10161

    Last Modified: 20 Apr 2025

    The object_common1 function in ext/standard/var_unserializer.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via crafted serialized data that is mishandled in a finish_nested_data call.

    Published: 19 Jan 2017
    7.5
    High

    CVE-2016-10162

    Last Modified: 20 Apr 2025

    The php_wddx_pop_element function in ext/wddx/wddx.c in PHP 7.0.x before 7.0.15 and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an inapplicable class name in a wddxPacket XML document, leading to mishandling in a wddx_deserialize call.

    Published: 19 Jan 2017
    5.5
    Medium

    CVE-2017-5842

    Last Modified: 17 Mar 2026

    The html_context_handle_element function in gst/subparse/samiparse.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted SMI file, as demonstrated by OneNote_Manager.smi.

    Published: 19 Jan 2017
    6.1
    Medium

    CVE-2016-3408

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bug 101813.

    Published: 18 Jan 2017
    9.8
    Critical

    CVE-2016-9676

    Last Modified: 20 Apr 2025

    Buffer overflow in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 18 Jan 2017
    5.3
    Medium

    CVE-2016-9677

    Last Modified: 20 Apr 2025

    Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors.

    Published: 18 Jan 2017
    9.8
    Critical

    CVE-2016-9678

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 18 Jan 2017
    9.8
    Critical

    CVE-2016-9679

    Last Modified: 20 Apr 2025

    Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer.

    Published: 18 Jan 2017
    7.5
    High

    CVE-2016-9680

    Last Modified: 20 Apr 2025

    Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive information from kernel memory via unspecified vectors.

    Published: 18 Jan 2017
    8.1
    High

    CVE-2016-10086

    Last Modified: 20 Apr 2025

    RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticated users to read or modify task information by leveraging incorrect permissions applied to a RESTful request.

    Published: 18 Jan 2017
    6.5
    Medium

    CVE-2016-3401

    Last Modified: 20 Apr 2025

    Unspecified vulnerability in Zimbra Collaboration before 8.7.0 allows remote authenticated users to affect integrity via unknown vectors, aka bug 99810.

    Published: 18 Jan 2017
    7.5
    High

    CVE-2016-3402

    Last Modified: 20 Apr 2025

    Unspecified vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to affect confidentiality via unknown vectors, aka bug 99167.

    Published: 18 Jan 2017
    7.5
    High

    CVE-2016-3404

    Last Modified: 20 Apr 2025

    Unspecified vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to affect integrity via unknown vectors, aka bug 103959.

    Published: 18 Jan 2017
    7.5
    High

    CVE-2016-3405

    Last Modified: 20 Apr 2025

    Multiple unspecified vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to affect integrity via unknown vectors, aka bugs 103961 and 104828.

    Published: 18 Jan 2017
    8.8
    High

    CVE-2016-3406

    Last Modified: 20 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to hijack the authentication of unspecified victims via vectors involving (1) the Client uploader extension or (2) extension REST handlers, aka bugs 104294 and 104456.

    Published: 18 Jan 2017
    6.1
    Medium

    CVE-2016-3407

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 104222, 104910, 105071, and 105175.

    Published: 18 Jan 2017
    6.1
    Medium

    CVE-2016-3410

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 103956, 103995, 104475, 104838, and 104839.

    Published: 18 Jan 2017
    6.1
    Medium

    CVE-2016-3411

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bug 103609.

    Published: 18 Jan 2017
    6.1
    Medium

    CVE-2016-3412

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 103997, 104413, 104414, 104777, and 104791.

    Published: 18 Jan 2017
    7.5
    High

    CVE-2016-3413

    Last Modified: 20 Apr 2025

    Unspecified vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to affect integrity via unknown vectors, aka bug 103996.

    Published: 18 Jan 2017
    6.5
    Medium

    CVE-2016-3414

    Last Modified: 20 Apr 2025

    Unspecified vulnerability in Zimbra Collaboration before 8.6.0 Patch 7 allows remote authenticated users to affect availability via unknown vectors, aka bug 102029.

    Published: 18 Jan 2017
    9.1
    Critical

    CVE-2016-3415

    Last Modified: 20 Apr 2025

    Zimbra Collaboration before 8.7.0 allows remote attackers to conduct deserialization attacks via unspecified vectors, aka bug 102276.

    Published: 18 Jan 2017
    6.1
    Medium

    CVE-2016-3999

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 104552 and 104703.

    Published: 18 Jan 2017
    7.5
    High

    CVE-2016-4019

    Last Modified: 20 Apr 2025

    Unspecified vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to affect integrity via unknown vectors, aka bug 104477.

    Published: 18 Jan 2017
    7.5
    High

    CVE-2016-6271

    Last Modified: 20 Apr 2025

    The Bzrtp library (aka libbzrtp) 1.0.x before 1.0.4 allows man-in-the-middle attackers to conduct spoofing attacks by leveraging a missing HVI check on DHPart2 packet reception.

    Published: 18 Jan 2017
    6.1
    Medium

    CVE-2016-6283

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action.

    Published: 18 Jan 2017